Documentation

Artifact types

Every artifact in the registry has a specific Gemara type. Here's what each one is, in the Gemara model's own terms — and where to browse it.

Most artifact types in the registry are catalogs — per Gemara, a structured set of related prose and relevant metadata — each collecting one kind of Gemara concept. The definitions below are quoted from the Gemara lexicon — follow the links for the full schema.

Control Catalogs

A Control is a mechanism, such as a safeguard or countermeasure, that asserts desired state (Layer 2) — the prescriptive objectives a system should meet. Browse controls →

Threat Catalogs

A Threat is a circumstance or event where the concepts of a vector are applied to a Capability in a specific context, resulting in the potential for negative impact (Layer 2). Browse threats →

Capability Catalogs

A Capability is a feature or function of a system; the primary component comprising an attack surface (Layer 2). Browse capabilities →

Guidance Catalogs

Guidance is prose intended to help bring about a desired outcome for a topic or generalized scenario, based on knowledge of relevant Vectors (Layer 1). Browse guidance →

Vector Catalogs

A Vector is an opportunity for an attacker to exploit a vulnerability in the system — or a path by which neglect could cause unintentional harm (Layer 1). Browse vectors →

Principle Catalogs

Principle Catalogs collect cross-cutting principles that motivate guidance and controls. Gemara's lexicon doesn't yet define "Principle" as a distinct term, so these are catalogs in the general sense — a structured set of related prose and relevant metadata. Browse principles →

Evaluators

Not a catalog: an evaluator is an executable Privateer plugin that produces evaluation evidence (Layer 5). See Evaluators.

📖 Full schemas and definitions for every type: gemara.openssf.org.